Effective date: June 19, 2026 · Last updated: June 19, 2026
General Provisions
Consilience (the “Company,” “we,” or “us”) establishes and discloses the following privacy policy in accordance with Article 30 of the Personal Information Protection Act (“PIPA”) to protect the personal information of data subjects (the “user” or “you”) and to handle related grievances promptly and smoothly. This policy applies to the Company's local-first ontology agent workspace desktop application (currently in private beta on macOS, with Windows coming soon; includes signed releases and automatic updates) and the associated payment, subscription, customer support, and website (consilience.md).
This policy is a formally effective, binding document even during the private beta period. Regardless of the fact that Pro features are offered free of charge during the private beta, the privacy obligations under this policy apply as written from the effective date.
Information about the personal information controller (operating entity) is as follows.
- Trade name (company): Consilience
- Representative: Youngtak Jo
- Business registration number: [Business Registration Number]
- Mail-order sales registration number: [Mail-Order Sales Registration Number]
- Business address: [Business Address]
- Phone: [Phone Number]
- Primary email: hello@consilience.md
- Hosting provider: [Hosting Provider]
Article 1 (Local-First Principle — What We Do Not Collect)
By design, Consilience does not send your content to our servers. Almost everything happens on your device, and data we can't reach doesn't even need to be protected. By design, the Company does not collect or retain the following.
- Note bodies. Your notes are ordinary
.md files on your disk and, by design, are not transmitted to our servers. - Knowledge graph, search index, regenerable layers. The knowledge graph is stored next to your notes as a portable, standard-format file, and every layer that can be rebuilt — including the search index — is stored only on your device and not transmitted to our servers. All of it is regenerated from your writing.
- No telemetry by default. We do not collect usage analytics, content tracking, or background uploads by default.
- No model training. We do not train AI models on your content or on any user data.
- No sensitive or unique identifying information. The Company does not collect or process sensitive information about beliefs, health, sex life, and the like (Article 23 of PIPA) or unique identifiers such as resident registration numbers (Article 24 of the same Act).
The boundaries of the exceptions are clear. With workspace sharing (creating a cloud link), web access (web search and URL fetching), and AI calls, data leaves your device only to the extent you explicitly turn the feature on or direct a task. If you don't use these features, all of your data — including your note bodies — stays entirely local.
Article 2 (Categories of Personal Information Processed and Collection Methods)
The categories of personal information the Company processes are as follows, and they are processed only to the extent you use the relevant feature.
- Paid-account email address and account identifier. Processed to create and manage paid subscription accounts and to verify identity.
- Payment identification information. We process partial payment-method information and billing metadata. However, sensitive payment information such as full card numbers is handled directly by the payment processor and seller, Paddle.com Market Ltd (Paddle, the UK-based Merchant of Record), and is not retained by the Company.
- Optional workspace sharing content. Only when you create a share link, the workspace bundle you select (notes, and optionally the knowledge graph) is uploaded to cloud storage. If you only export to a file or don't use the feature, everything stays local.
- Customer inquiry content. We process the information you provide directly in emails and inquiries.
- Optional diagnostic information. We process error and usage diagnostic data only if you opt in.
- Content processed when using the web access feature. Only if you turn on the web access feature, we process the search terms, URLs, and fetched page content you enter or request (off by default).
- Text sent for AI tasks. When the agent calls an AI model to answer or work, only the text needed for that task is sent to the external model provider. Your entire notes or knowledge graph are not sent wholesale.
- Technical information. During automatic updates and license verification, information such as IP address, app version, and operating system may be unavoidably processed.
Collection methods. Personal information is collected as (1) information you enter directly (account email and inquiry content) and (2) information processed automatically in the course of using features (payment, optional diagnostics, workspace sharing, AI calls, automatic updates). Among the automatically processed items, diagnostics, web access, AI transmission, and workspace sharing are processed only to the extent you explicitly turn them on or direct a task.
Article 3 (Purposes of Processing Personal Information)
The Company processes personal information for the following purposes, and if the purpose of processing changes, it takes necessary measures such as obtaining separate consent under Article 18 of PIPA.
- Creating and managing paid subscription accounts and verifying identity
- Payment, billing, tax handling, and refunds (processed via Paddle)
- Providing the optional workspace sharing feature (when you create a share link)
- Responding to customer inquiries and providing technical support
- Processing optional (opt-in) diagnostic information to improve product stability
- Performing AI agent features (sending the text needed for a task to the model provider)
- Processing the relevant content when providing the web access feature (web search and URL fetching) (off by default, user opt-in)
Article 4 (Processing and Retention Period of Personal Information)
The Company processes and retains personal information within the retention and use period required by law or consented to by the data subject. When the processing purpose is achieved or the retention period elapses, it destroys the relevant personal information without delay. The processing and retention period by category is as follows.
- Account email and account identifier: From the subscription/account maintenance period until membership withdrawal or subscription cancellation (or until the end of any legally required retention period).
- Payment-related records: Retained for the retention period set by relevant laws such as the Act on Consumer Protection in Electronic Commerce and the Framework Act on National Taxes. The payment information held by Paddle, the entity handling payment, tax, and refunds, and the transaction records held by the Company are processed separately by holding entity and scope.
- Workspace sharing content: Retained for the validity period of the share link (until expiry), and processed without delay upon expiry, cancellation, or a deletion request.
- Customer inquiries: Destroyed after a reasonable period needed for dispute response and quality management has passed following completion of the inquiry.
- Optional diagnostic information: Retained until the collection purpose is achieved; if you withdraw your opt-in consent, processing stops immediately.
Where there is a legal retention obligation, we store such information separately, specifying the governing law and the retained items, and destroy it without delay once the retention period ends.
Article 5 (Personal Information of Children Under 14)
The Company does not provide services aimed at children under 14 and does not intentionally collect the personal information of children under 14. If processing requiring a legal guardian's consent occurs, the Company obtains the legal guardian's consent and explains the consent verification method in accordance with Article 22-2 of PIPA. If the Company becomes aware that the personal information of a child under 14 was collected without a legal guardian's consent, it destroys that information without delay.
Article 6 (Provision of Personal Information to Third Parties)
The Company does not provide personal information to third parties except where the data subject consents or there is a special provision in law. The Company currently does not provide data subjects' personal information to any separate third party; transfers of personal information to AI model providers, cloud storage providers, Paddle, and the like are handled under Article 7 (Entrustment of Processing) and Article 8 (Overseas Transfer) of this policy. If third-party provision becomes necessary in the future, the Company will give prior notice of the recipient, purpose, items provided, and retention/use period, and obtain consent.
Article 7 (Entrustment of Personal Information Processing)
For smooth service delivery, the Company entrusts personal information processing tasks externally as follows. When entering an entrustment contract, in accordance with Article 26 of PIPA, the Company specifies in the contract matters concerning the safe management of personal information, restrictions on re-entrustment, and responsibilities such as management/supervision and damages, and supervises whether the trustee processes personal information safely.
- Paddle.com Market Ltd (Paddle, UK-based Merchant of Record): Payment, billing, tax (VAT, etc.), and refund processing.
- Amazon Web Services, Inc. (AWS, United States): Cloud storage of the workspace bundle uploaded when you create a share link.
- OpenRouter, Inc. (United States): Routing the text needed for an agent task to a model provider. OpenRouter forwards the request to model providers such as OpenAI, Anthropic, and Google.
- Supabase, Inc. (United States): Operating the account/authentication backend and the edge functions that relay agent (AI) and web requests, and storing any opt-in diagnostic data.
- Exa Labs, Inc. (United States) / Mapbox, Inc. (United States): Processing your query when you use web search (Exa) or the map features (Mapbox); used only when you invoke the feature.
If the content of the entrusted work or the trustee changes, the Company will disclose it without delay through this privacy policy. Where some trustees are located overseas, matters concerning that overseas transfer are also disclosed in Article 8.
Article 8 (Overseas Transfer of Personal Information)
In accordance with Article 28-8 of PIPA, the Company transfers personal information overseas as follows. The basis for each transfer differs by the nature of the feature. Payment occurs to the extent necessary to perform the paid subscription contract, while features you explicitly turn on (opt-in) — such as workspace sharing, web access, and AI calls — are based on the data subject's consent (Article 28-8(1) of the same Act). The items transferred, the country, timing, and method of transfer, the recipient, the purpose of use and retention/use period, and the method of refusal are as follows.
- Paddle.com Market Ltd — Country: United Kingdom.
- Items transferred: payment identification information and billing metadata (including email).
- Timing and method: transmitted over an encrypted channel at the moment you make a paid payment.
- Recipient and contact: Paddle.com Market Ltd (for inquiries, contact hello@consilience.md for guidance).
- Purpose of use: payment, tax, and refund processing.
- Retention/use period: the retention period under relevant laws and the period under Paddle's policy.
- Method and effect of refusal: you can refuse by not proceeding with payment; if you refuse, you cannot use paid payment.
- OpenRouter, Inc. — Country: United States.
- Items transferred: the text needed for an agent task.
- Timing and method: transmitted over an encrypted channel at the moment you use an AI feature to direct a task.
- Recipient and contact: OpenRouter, Inc.; for guidance, contact hello@consilience.md. OpenRouter forwards the request to model providers such as OpenAI, Anthropic, and Google (all in the United States).
- Purpose of use: generating agent responses.
- Retention/use period: processed only for the time needed to generate the response; not used to train models.
- Method and effect of refusal: you can refuse by not using AI features; if you refuse, that AI feature is unavailable, but local features remain usable.
- Amazon Web Services, Inc. (AWS) — Country: United States.
- Items transferred: the workspace bundle you uploaded to create a share link.
- Timing and method: transmitted over an encrypted channel at the moment you create a workspace share link.
- Recipient and contact: Amazon Web Services, Inc.; for guidance, contact hello@consilience.md.
- Purpose of use: providing the workspace share link.
- Retention/use period: the validity period of the share link (7 days after creation) and until a deletion request is processed.
- Method and effect of refusal: you can refuse by not using share-link creation (using only file export); if you refuse, all data stays entirely local.
Other recipients (United States). In addition, the following receive limited data in the United States: Supabase, Inc. (account/authentication backend and relaying AI/web requests — account email and identifier, and any opt-in diagnostics), Exa Labs, Inc. (your search query, when you use web search), and Mapbox, Inc. (the place/address query, when you use the map features). Each transfer occurs over an encrypted channel only when you maintain an account or use the relevant feature, is processed only as needed to provide it, and can be refused by not creating an account or not using that feature — local features remain usable.
Summary of the effect of refusal. If you don't use features that involve overseas transfer (payment, workspace sharing, web/AI), your note bodies stay entirely local and no overseas transfer occurs.
Article 9 (Procedure and Method of Destroying Personal Information)
When personal information becomes unnecessary — for instance, because the retention period has elapsed or the processing purpose has been achieved — the Company destroys it without delay.
- Destruction procedure. The personal information for which grounds for destruction have arisen is selected and destroyed after confirmation by the personal information protection officer.
- Destruction method. Information in electronic file form is permanently deleted by a method that prevents recovery and reproduction, and personal information recorded on paper documents is shredded or incinerated.
- Nature of local data. Local data such as notes, the knowledge graph, and the search index is deleted by you directly on your device; data not stored on our servers is not subject to destruction by the Company.
- Server-side data. Data stored on the server — such as workspace sharing content, account information, and payment records — is destroyed by the above method when the retention period elapses or upon a deletion request. However, information subject to a legal retention obligation is destroyed after the retention period ends.
Article 10 (Rights and Obligations of Data Subjects and Legal Guardians, and How to Exercise Them)
You may exercise the following rights against the personal information controller at any time.
- Requesting access to personal information
- Requesting correction or deletion in case of errors, etc.
- Requesting suspension of processing
- Withdrawing consent
You may exercise your rights via email (hello@consilience.md), an inquiry channel, or in-app settings, and the Company takes action within the period set by relevant laws (in principle, within 10 days from the date a request for access, correction, deletion, or suspension of processing is received). A data subject may exercise rights through a legal guardian or an authorized agent, in which case a power of attorney under the Enforcement Rules of PIPA must be submitted. The Company informs you of the result of handling access, correction, deletion, or suspension requests and, if it refuses a request, notifies you of the reason.
Self-determination over local data. Because your notes and knowledge graph are standard-format files on your device, you can directly access, modify, or delete them, or move (port) them to other tools. You can also turn diagnostics, web access, AI transmission, and workspace sharing on (opt-in) or off (opt-out) at any time in the in-app settings.
Article 11 (Installation, Operation, and Refusal of Automatic Collection Devices)
The Consilience desktop app itself does not operate separate automatic collection devices such as web cookies. However, the Paddle payment page, the web access feature, web-based components, and our website (consilience.md) may use cookies, local storage, and identifiers to provide the service and ease of use.
- Purpose of installation/operation. Maintaining login state, processing payment, and providing service convenience.
- Method of refusal. You can refuse or delete cookie storage in your web browser or app settings. However, if you refuse cookie storage, some features such as payment may be restricted.
Article 12 (Measures to Ensure the Safety of Personal Information)
In accordance with Article 29 of PIPA and related laws, the Company takes the following measures to ensure the safety of personal information.
- Administrative measures. Establishing and implementing an internal management plan, minimizing personal information handlers, and providing regular training.
- Technical measures. Managing and differentially granting access rights to the personal information processing system, encrypting transmission channels and content stored in the cloud, preventing forgery/alteration through retention and inspection of access logs, and blocking malware via security programs.
- Physical measures. Access control over servers and storage media (where applicable).
Local-first security model. Because regenerable layers such as the knowledge graph and search index are kept on your device, the surface exposed to the server is structurally minimized. We also guarantee the integrity of distributions with signed releases and automatic updates.
Article 13 (Personal Information Protection Officer)
The Company designates a personal information protection officer as follows to take overall responsibility for personal information processing tasks and to handle data subjects' inquiries, complaints, and remedies related to personal information processing.
- Personal information protection officer: [Officer Name]
- Title: [Officer Title]
- Contact: hello@consilience.md
Data subjects may direct all inquiries, complaints, and remedies related to personal information protection to the personal information protection officer, and the Company will respond and act without delay.
Article 14 (Remedies for Rights Infringement)
To obtain remedies for personal information infringement, data subjects may apply for dispute resolution or consultation to the agencies below.
- Personal Information Dispute Mediation Committee: (no area code) 1833-6972 / www.kopico.go.kr
- Personal Information Infringement Report Center (KISA): (no area code) 118 / privacy.kisa.or.kr
- Supreme Prosecutors' Office Cybercrime Investigation Division: (no area code) 1301 / www.spo.go.kr
- National Police Agency Cyber Investigation Bureau: (no area code) 182 / ecrm.police.go.kr
In addition, if your rights or interests are infringed by a disposition or omission of the personal information controller, you may file an administrative appeal under the Administrative Appeals Act or bring an administrative suit under the Administrative Litigation Act.
Article 15 (Notice on Payment and Agent Processing Controls)
- Merchant of Record. Payment for paid subscriptions is processed through Paddle.com Market Ltd (Paddle, UK-based). As the legal seller/reseller, Paddle handles billing, tax (VAT, etc.), and refunds, and is the entity that processes email and payment-method identification information during payment. Your note bodies remain local regardless of payment.
- Agent change approval model. Every change the agent makes (creating notes, editing files, running commands) goes through the approval method you set. Processing control rests with you.
- Accuracy of AI output. AI model output may be inaccurate or incomplete, and the Company does not guarantee its accuracy or completeness. Please verify important decisions yourself.
- Data portability. Because notes and the knowledge graph are standard-format files, you can freely export your data at any time.
Article 16 (Changes to and Notice of the Privacy Policy)
This policy applies from the effective date. When the Company establishes or changes this policy, it posts it in-app and on the website (consilience.md) so that data subjects can easily check it. When changing this policy, the Company gives prior notice of the changes, reasons, and effective date, and for important changes it provides notice sufficiently in advance of the effective date. The Company retains previous versions so that the change history can be reviewed.
If pricing or benefits change in the course of transitioning from the private beta to general availability, the Company will give prior notice, and if anything affects personal information processing, it will be reflected through amendment and notice of this policy.
See also: Terms of Service · Refund Policy · Data Processing Notice · Security.